tcpdump mailing list archives

RE : RE : capturing and injection on same interface


From: "Jacky Buyck" <jacky.buyck () wanadoo fr>
Date: Fri, 9 Jan 2004 14:59:51 +0100


Ok I see.
But I still thinking that it can be more simple to use 2 interfaces.
MITM be more simple if a make a real cut between your two system. But
that is true that my vision is more oriented in a test lab way so ...

-----Message d'origine-----
De : Alberto Ornaghi [mailto:alor () antifork org] 
Envoyé : vendredi 9 janvier 2004 14:27
À : Jacky Buyck; tcpdump-workers () tcpdump org
Objet : Re: RE : [tcpdump-workers] capturing and injection on same
interface


Jacky Buyck wrote:
Hmmmm ... The better can be simply to use a second interface. What is 
the utility to modify and reinject a packet on the same link than the 
good one : the receiver will always received the good packet first 
ignoring your modified one. No ???

in a mitm attack the victim will not receive the packet until you 
forwardi it...

Except if you've a real need for this.

think about a bridge in userland. since it has to be bidirectional, what

you inject on one iface will be recaptured back as it was received from 
that interface...

bye

-- 

    --==> ALoR <==---------------------- -  -   -

  There are only 10 types of people in this world...
  Those who understand binary, and those who don't.

-
This is the TCPDUMP workers list. It is archived at
http://www.tcpdump.org/lists/workers/index.html
To unsubscribe use mailto:tcpdump-workers-request () tcpdump org?body=unsubscribe


Current thread: